# The tool runtime: the base every module written in this toolchain is compiled on top of, and the # container a node runs to serve them. It is handed the broker credential and the assigned modules' # entrypoints at deploy time and serves them. # # **Built from this repository alone.** It used to copy in a compiled output directory that is not # in source control, and resolve the mesh's own toolkit to a sibling checkout on the same disk — so # it could only be produced on a workstation with two repositories laid out side by side, and its # fingerprint was then typed into every module's recipe by hand. That put the one artifact the whole # toolchain stands on outside the toolchain: nothing could rebuild it, so nothing could check it, # and the rule that catches a base moving had no version on the far end of its edge and could never # fire (novox/hq issue 044). # # Debian rather than Alpine, and root rather than an unprivileged user, because that is what the # image actually in service is — and modules have already been built against it, one of which # installs a package with Debian's package manager. This recipe said Alpine while serving Debian for # as long as nobody could rebuild it to notice. Changing the operating system under every module is # a separate decision from making this buildable, and is not being taken here. FROM node:22-bookworm-slim AS build # git, because a dependency named by a git URL is fetched by git and this image does not carry it. # Only in the build stage: what it is needed for happens here, and a runtime that can clone is a # runtime that can be made to clone. RUN apt-get update \ && apt-get install -y --no-install-recommends git ca-certificates \ && rm -rf /var/lib/apt/lists/* WORKDIR /app COPY package.json package-lock.json ./ # Development dependencies included: the compiler is one of them, and so is the toolkit's own — it # builds itself on install, which is what lets it be named by a git URL rather than fetched from a # package registry this mesh does not yet run. RUN npm install --no-audit --no-fund COPY tsconfig.json ./ COPY src ./src RUN npm run build # Dropped after compiling rather than reinstalled in the next stage, which would need git there too. RUN npm prune --omit=dev # Everything the modules compile against and run on, and nothing that only the build needed. FROM node:22-bookworm-slim WORKDIR /app COPY package.json ./ COPY --from=build /app/node_modules ./node_modules COPY --from=build /app/dist ./dist ENTRYPOINT ["node", "dist/main.js"]